Brocade SANnav 命令行界面(CLI)脚本组件存在对 Shell 元字符输入验证不足的缺陷,使得已认证用户能够突破受管交换机上的受限执行环境。拥有命令执行权限的攻击者可利用此漏洞,绕过命令白名单限制,在目标 Fabric 交换机上执行未授权的 Shell 命令,从而获取交换机完全的管理员访问权限。此漏洞影响所有低于 3.0.1a 版本的 Brocade SANnav。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82368 | 8.7 HIGH | Brocade SANnav 3.0.1a前本地非授权访问漏洞 |
| CVE-2026-82370 | 8.6 HIGH | Unauthenticated remote command injection in the Brocade SANnav orchestrator HTTP service |
No comments yet